CVE-2025-49891 | riotweb Contact Info Widget Plugin up to 2.6.2 on WordPress cross site scripting
A vulnerability was found in riotweb Contact Info Widget Plugin up to 2.6.2 on WordPress and classified as problematic. The affected element is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-49891. The attack may be launched remotely. There is no exploit available.